{"id":"CVE-2019-25160","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetlabel: fix out-of-bounds memory accesses\n\nThere are two array out-of-bounds memory accesses, one in\ncipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk()","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetlabel: fix out-of-bounds memory accesses\n\nThere are two array out-of-bounds memory accesses, one in\ncipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk().  Bot…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","cwe":["CWE-125"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 2.6.19, < 3.16.66","linux_kernel >= 3.17.0, < 3.18.137","linux_kernel >= 3.19.0, < 4.4.177","linux_kernel >= 4.5.0, < 4.9.163","linux_kernel >= 4.10.0, < 4.14.106","linux_kernel >= 4.15.0, < 4.19.28","linux_kernel >= 4.20.0, < 4.20.15"],"patched":["linux_kernel 4.20.15"],"published":"2024-02-26","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-25160","references":[{"url":"https://git.kernel.org/stable/c/1c973f9c7cc2b3caae93192fdc8ecb3f0b4ac000","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5578de4834fe0f2a34fedc7374be691443396d1f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/97bc3683c24999ee621d847c9348c75d2fe86272","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c61d01faa5550e06794dcf86125ccd325bfad950","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc18101f95fa6e815f426316b8b9a5cee28a334e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3713abc4248aa6bcc11173d754c418b02a62cbb","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fbf9578919d6c91100ec63acf2cba641383f6c78","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fcfe700acdc1c72eab231300e82b962bac2b2b2c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c973f9c7cc2b3caae93192fdc8ecb3f0b4ac000","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/5578de4834fe0f2a34fedc7374be691443396d1f","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/97bc3683c24999ee621d847c9348c75d2fe86272","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/c61d01faa5550e06794dcf86125ccd325bfad950","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/dc18101f95fa6e815f426316b8b9a5cee28a334e","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/e3713abc4248aa6bcc11173d754c418b02a62cbb","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/fbf9578919d6c91100ec63acf2cba641383f6c78","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/fcfe700acdc1c72eab231300e82b962bac2b2b2c","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00745,"epssPercentile":0.52871,"ingestedAt":"2026-08-04T10:39:38.046Z","slug":"CVE-2019-25160","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnetlabel: fix out-of-bounds memory accesses\n\nThere are two array out-of-bounds memory accesses, one in\ncipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk().  Both\nerrors are embarassingly simple, and the fixes are straightforward.\n\nAs a FYI for anyone backporting this patch to kernels prior to v4.8,\nyou'll want to apply the netlbl_bitmap_walk() patch to\ncipso_v4_bitmap_walk() as netlbl_bitmap_walk() doesn't exist before\nLinux v4.8.\n\n## Affected\n\n- `linux_kernel >= 2.6.19, < 3.16.66`\n- `linux_kernel >= 3.17.0, < 3.18.137`\n- `linux_kernel >= 3.19.0, < 4.4.177`\n- `linux_kernel >= 4.5.0, < 4.9.163`\n- `linux_kernel >= 4.10.0, < 4.14.106`\n- `linux_kernel >= 4.15.0, < 4.19.28`\n- `linux_kernel >= 4.20.0, < 4.20.15`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 4.20.15`","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}